
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
Two bills from prominent senators offer ideas to address cybersecurity threats linked to frontier artificial intelligence models, including the creation of a federal investigation board with subpoena power and a Commerce Department-led board bringing together agencies and industry stakeholders to establish safety standards.
Summary
The Cybersecurity and AI Board of Investigations Act , introduced by Sen. Edward Markey (D-MA) on Sept. 24, would establish a new board, akin to the National Transportation Safety Board, to address major cybersecurity incidents and conduct assessments addressing threats.
Senate Intelligence ranking member Mark Warner (D-VA) and Brian Schatz (D-HI) are taking a different approach in their Artificial Intelligence Risk Management and Security Act to address AI threats through the creation of an Artificial Intelligence Safety Board under the Commerce Department. The Warner-Schatz bill was also introduced on Sept. 24.
Both bills come as interest in the safety of frontier AI models has increased significantly, in part due to a Sept. 12 essay from Anthropic CEO Dario Amodei on slowing the pace of frontier AI model development which was backed by OpenAI CEO Sam Altman. Tensions over AI safety led to a push in the House Energy and Commerce Committee last week where Democrats emphasized the need to address AI safety for the sake of humankind.
The House recessed on Sept. 16 after a three-day session and is expected to return after Election Day. With new bills in the Senate, Markey, Warner and Schatz are making a push to put their marks on AI priorities before the Senate recess begins in early October.
Markey’s proposed board would “demand answers from companies and government agencies involved in major cybersecurity incidents and to deliver clear assessments of cyber threats and measures to prevent such threats,” according to a release from his office. The release says the bill will: Establish the Cybersecurity and AI Board of Investigations as a non-regulatory investigative board tasked with developing an authoritative account of major cybersecurity incidents; Provide the Board subpoena power to ensure access to all relevant information and evidence needed to investigate incidents fully; Require public reporting on investigations, which would include recommendations for action by relevant institutions, including federal agencies and industry. Markey’s bill comes after efforts in the Biden administration to stand up a Cyber Safety Review Board modeled after the NSTB to review significant cyber incidents and make recommendations.
The board was created through a 2021 cyber executive order and conducted investigations into the 2021 Log4j vulnerability, ransomware group Lapsus$ and a review of the 2023 Microsoft Exchange Online Intrusion. Early efforts to start an investigation into the Salt Typhoon campaign in December 2024 were effectively halted on the first day of the second Trump administration, when the Department of Homeland Security fired all private sector CSRB members. Markey said in the release, “Despite the unprecedented depth and scale of recent AI-enabled cyber attacks, the public is learning critical details piecemeal.
Building stronger defenses requires a full accounting of what goes wrong, and we cannot depend on companies with little incentive to disclose their failures to give us one.” “We need the Cybersecurity and AI Board of Investigations to get to the bottom of major incidents and give companies and the government the critical information necessary to build resilience and better secure our economy and our country,” Markey said. The Warner-Schatz bill takes a different approach with a safety board at Commerce “to evaluate emerging AI risks and establish technical safety and security standards,” according to a release from Warner’s office . The board would include representatives from the National Institute of Standards and Technology, the Cybersecurity and Infrastructure Security Agency, the National Security Agency and the Treasury Department.
The board would also feature “independent technical experts,” according to the Warner release. The release says, “Critically, developers of frontier AI models would be required to provide the Board access to their models at least 45 days before public release, including model weights, configuration files, runtimes, and software libraries necessary to operate the model, allowing experts to evaluate powerful models before deployment.” “The legislation would also require AI developers to create and follow Model Safety Plans identifying the capabilities and risks of their systems, the specific steps they will take to mitigate those risks, and the corporate officer responsible for implementing the plan,” the release says. The board would also be responsible for developing “enforceable standards for evaluating frontier models and securing testing environments, including safeguards and monitoring procedures for models capable of discovering and exploiting software vulnerabilities without direct human prompting,” according to the release.
The bill sets up civil penalties for developers who don’t comply with the standards, at up to $250,000 per violation, per day. Another provision in the bill directs NIST to create a “secure reporting process and a national AI incident database to track AI safety and security incidents, recurring flaws, and near misses so researchers, government agencies, and developers can learn from failures across different systems,” according to the release. The database would be run in coordination with CISA.
Warner said in the release, “If a model is capable of finding and exploiting vulnerabilities in a bank, a water system, or our electric grid, we ought to know that before it is released to the public – not after something goes catastrophically wrong.
KazaSec's take
Incidents like this rarely start with the headline event itself — they usually trace back to an exposed remote-access endpoint, an unpatched perimeter system, or a credential phished weeks earlier. The organizations that recover fastest are the ones that tested their defenses and their incident response plan before they needed them.
Coverage details
Related security advisories
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.